Legal
Privacy policy
What ASYST collects, why it is collected, who else processes it, how long it is kept, and how to have it removed. Last updated 29 July 2026.
1. Who this policy is from
ASYST is a product of STREaMLiNE, an Australian business. This policy covers the ASYST marketing site and the ASYST application. Questions, requests and complaints go to admin@push2streamline.com.
2. What we collect
Three things, and nothing else.
Identity data from your sign-in provider
ASYST authenticates through Microsoft, Google or GitHub. When you sign in, we receive from that provider your email address, your display name and the provider's subject identifier for you, which is the opaque string that lets us recognise you on your next visit. We never receive your password, because you never give ASYST one.
Project content you upload
The briefs, statements of work and concept descriptions you submit, and every artefact the pipeline generates from them: requirements, architectures, the risk register, the verification and validation matrix, the traceability chain and the Need Analysis document.
Cookieless usage analytics
Aggregate page views and performance measurements for the marketing site. No cookie is set, no cross-site identifier is created and no profile is built. We cannot tie an analytics event to a person, and neither can our analytics provider.
3. Why we collect it
- Identity data so we can authenticate you, keep your projects separate from everybody else's, and contact you about your account.
- Project content so the pipeline can generate the model you asked for and so you can return to it later. It is processed on your instruction.
- Analytics so we know which pages are read and which are slow.
We do not sell personal information, we do not run advertising, and we do not use your project content to market to anyone else.
4. Hosting and sub-processors
Running ASYST means other companies process some of this data on our behalf.
- Vercel hosts the marketing site and the application front end, and provides the cookieless analytics described above.
- Neon provides the managed PostgreSQL database that stores your account record and your project data.
- The large language model provider that runs the generation pipeline. Producing a system model requires sending your project content to it. This is inherent to how ASYST works, and it is the one place your content leaves our own infrastructure.
5. Cookies, and why there is no consent banner
The marketing site sets no cookies at all. Its analytics are cookieless, which is why you are not being asked to consent to anything: there is nothing to consent to.
The application sets one cookie, a session cookie, which keeps you signed in between requests. It is strictly necessary for the service to work, it contains an opaque reference rather than your details, and it is not used to track you anywhere.
6. How long we keep it
Your account record and project content are kept for as long as your account exists, because a system model is a working document you will come back to. When you ask us to delete your account, the account, its projects and every artefact generated from them are removed. Analytics data is aggregate and is not linked to you, so it is unaffected.
7. Your rights, and how to use them
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account and everything in it. Email admin@push2streamline.com from the address you sign in with, so we can be confident the request is yours.
While ASYST is in early access these requests are handled manually rather than through a self-service control in the application. We will confirm in writing when a deletion has been carried out.
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are in the United Kingdom or the European Union, we honour the same access, correction and erasure requests. If you are not satisfied with how we have handled a request, tell us first at the address above, and you retain the right to complain to your own privacy regulator.
8. Security
Authentication is delegated to Microsoft, Google or GitHub, so ASYST holds no passwords to lose. Data is transmitted over TLS and stored with the managed providers listed above. No system is perfectly secure, and we do not claim otherwise.
9. Changes to this policy
If this policy changes we will update the date at the top of this page. Where a change materially affects what we collect or who processes it, we will email account holders rather than rely on you noticing.
10. Contact
Privacy questions, access requests and deletion requests: admin@push2streamline.com.